|
31096
|
23510
|
76
|
5
|
55b9c2a0af78b6998bac3614dedc7187e37057ea
|
0
|
Runtime and UI acceptance
|
0
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
runtime-acceptance:
name: Runtime and UI acceptance
runs-on: ubuntu-latest
env:
DATABASE_URL: postgresql://postgres:postgres@127.0.0.1:5432/digital_employee_os_ci?schema=public
REDIS_URL: redis://127.0.0.1:6379
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run real DB and Redis acceptance
run: pnpm check:runtime
- name: Install Playwright browser
run: pnpm --filter web exec playwright install --with-deps chromium
- name: Run UI acceptance
run: pnpm check:ui
env:
# O1:runtime 验收的遗留 delayed job 不得漏进 UI 阶段共享的 BullMQ 队列,
# Redis 逻辑库隔离(镜像本地 /2 vs /3 约定)。
REDIS_URL: redis://127.0.0.1:6379/1
services:
postgres:
image: postgres:16
env:
POSTGRES_DB: digital_employee_os_ci
POSTGRES_PASSWORD: postgres
POSTGRES_USER: postgres
ports:
- 5432:5432
options: --health-cmd "pg_isready -U postgres -d digital_employee_os_ci" --health-interval 5s --health-timeout 5s --health-retries 20
redis:
image: redis:7
ports:
- 6379:6379
options: --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
runtime-acceptance
|
["static-governance"]
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1787411987
|
1787411590
|
1787411987
|
|
0
|
|
0
|
Edit
Delete
|
|
31097
|
23511
|
76
|
5
|
28ea42cca5364bd425358f803436ae5c8f9bc687
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27193
|
3
|
1787411988
|
1787412510
|
1787411987
|
1787412510
|
|
0
|
|
0
|
Edit
Delete
|
|
31098
|
23511
|
76
|
5
|
28ea42cca5364bd425358f803436ae5c8f9bc687
|
0
|
Runtime and UI acceptance
|
0
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
runtime-acceptance:
name: Runtime and UI acceptance
runs-on: ubuntu-latest
env:
DATABASE_URL: postgresql://postgres:postgres@127.0.0.1:5432/digital_employee_os_ci?schema=public
REDIS_URL: redis://127.0.0.1:6379
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run real DB and Redis acceptance
run: pnpm check:runtime
- name: Install Playwright browser
run: pnpm --filter web exec playwright install --with-deps chromium
- name: Run UI acceptance
run: pnpm check:ui
env:
# O1:runtime 验收的遗留 delayed job 不得漏进 UI 阶段共享的 BullMQ 队列,
# Redis 逻辑库隔离(镜像本地 /2 vs /3 约定)。
REDIS_URL: redis://127.0.0.1:6379/1
services:
postgres:
image: postgres:16
env:
POSTGRES_DB: digital_employee_os_ci
POSTGRES_PASSWORD: postgres
POSTGRES_USER: postgres
ports:
- 5432:5432
options: --health-cmd "pg_isready -U postgres -d digital_employee_os_ci" --health-interval 5s --health-timeout 5s --health-retries 20
redis:
image: redis:7
ports:
- 6379:6379
options: --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
runtime-acceptance
|
["static-governance"]
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1787412510
|
1787411987
|
1787412510
|
|
0
|
|
0
|
Edit
Delete
|
|
31099
|
23512
|
76
|
5
|
d0abf16e0287850cbb497074a866f1b35074dbb1
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27194
|
2
|
1787412511
|
1787412601
|
1787412510
|
1787412602
|
|
0
|
|
0
|
Edit
Delete
|
|
31101
|
23513
|
13
|
5
|
6c80c00976d1c5ac4aaa5f76d10cf1e7b4f59448
|
0
|
Analyze (java)
|
1
|
name: CodeQL Analysis
"on":
push:
name: CodeQL Analysis
"on":
push:
branches: [develop, master, main]
pull_request:
branches: [develop, master, main]
schedule:
# 每周一凌晨3点运行
- cron: '0 3 * * 1'
jobs:
analyze:
name: Analyze (java)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Setup Java
uses: actions/setup-java@v4
with:
cache: gradle
distribution: temurin
java-version: "17"
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: ${{ matrix.language }}
queries: +security-extended,security-and-quality
- name: Grant Execute Permission
run: chmod +x ./gradlew
- name: Build
run: ./gradlew assembleDebug --stacktrace
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
with:
category: /language:${{ matrix.language }}
timeout-minutes: "30"
strategy:
fail-fast: "false"
matrix:
language:
- java
permissions:
actions: read
contents: read
security-events: write
...
|
analyze
|
null
|
["ubuntu-latest"]
|
27195
|
2
|
1787540400
|
1787540423
|
1787540400
|
1787540423
|
|
0
|
|
0
|
Edit
Delete
|
|
31102
|
23514
|
57
|
5
|
e759f5e4509e93cc4968259cc6d6a64bc73c09f1
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27196
|
2
|
1787560925
|
1787561016
|
1787560925
|
1787561016
|
|
0
|
|
0
|
Edit
Delete
|
|
31103
|
23515
|
57
|
5
|
43fb473a0f44228eb0ac2dc41e920e3e5ab523b5
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27197
|
2
|
1787563172
|
1787563262
|
1787563171
|
1787563263
|
|
0
|
|
0
|
Edit
Delete
|
|
31104
|
23516
|
75
|
5
|
5b6ffb2fd47829470408617bee019a0a3912b7b7
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27198
|
1
|
1787563749
|
1787563789
|
1787563748
|
1787563789
|
|
0
|
|
0
|
Edit
Delete
|
|
31106
|
23517
|
62
|
5
|
ca134d5514b10ecb8b367c953c3284aaa5984f8a
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27200
|
2
|
1787564571
|
1787564661
|
1787564570
|
1787564661
|
|
0
|
|
0
|
Edit
Delete
|
|
31108
|
23518
|
57
|
5
|
ba48645a4237735976c13184c3aac435bc868949
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27201
|
2
|
1787581007
|
1787581098
|
1787581007
|
1787581098
|
|
0
|
|
0
|
Edit
Delete
|
|
31109
|
23519
|
76
|
5
|
5cb2f1cc2f9953d47fa0bcfac541400d01603f78
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27202
|
1
|
1787631680
|
1787634793
|
1787631678
|
1787634793
|
|
0
|
|
0
|
Edit
Delete
|
|
31111
|
23520
|
80
|
5
|
49e97bd63c64e1d0484db4acffd63d40ab27bbbe
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27204
|
2
|
1787673172
|
1787673196
|
1787673170
|
1787673196
|
|
0
|
|
0
|
Edit
Delete
|
|
31113
|
23521
|
57
|
5
|
7a7e42422a19f6ad4c86d4cd320119a7fc912885
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27205
|
2
|
1787675667
|
1787675695
|
1787675666
|
1787675695
|
|
0
|
|
0
|
Edit
Delete
|
|
31114
|
23522
|
57
|
5
|
f094101357dc511e450e0e18fab5c91baaed9865
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27206
|
1
|
1787676047
|
1787676094
|
1787676046
|
1787676095
|
|
0
|
|
0
|
Edit
Delete
|
|
31115
|
23523
|
57
|
5
|
8e23fd115535dda184b584cb62396fa8286ef383
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27207
|
1
|
1787705227
|
1787705287
|
1787705225
|
1787705287
|
|
0
|
|
0
|
Edit
Delete
|
|
31116
|
23524
|
81
|
5
|
464b90ba5bf51536276468811aac396e51d66892
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
steps:
- name: Checkout service system
uses: actions/checkout@v4
with:
path: service-system
- name: Checkout locked Digital Employee OS baseline
uses: actions/checkout@v4
with:
path: digital-employee-os
ref: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.DIGITAL_EMPLOYEE_OS_READ_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build locked Digital Employee OS compatibility packages
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" install --frozen-lockfile
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/skill-runtime build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/tool-runtime build
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: service-system
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27208
|
2
|
1787705287
|
1787705294
|
1787705280
|
1787705295
|
|
0
|
|
0
|
Edit
Delete
|
|
31118
|
23525
|
57
|
5
|
cf66be23009de5ecbefad6083c173eb1df3f4c8b
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27209
|
1
|
1787705553
|
1787705605
|
1787705552
|
1787705605
|
|
0
|
|
0
|
Edit
Delete
|
|
31119
|
23526
|
80
|
5
|
7307924582aa9ace4042b51463833ebd9bc9d17e
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
DIGITAL_EMPLOYEE_OS_SHA: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout device cloud with history
uses: actions/checkout@v4
with:
fetch-depth: "0"
path: device-cloud
- name: Checkout pinned Digital Employee OS
uses: actions/checkout@v4
with:
fetch-depth: "1"
path: digital-employee-os
ref: ${{ env.DIGITAL_EMPLOYEE_OS_SHA }}
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.OS_REPO_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install device-cloud dependencies
run: pnpm install --frozen-lockfile
- name: Install pinned OS dependencies
run: pnpm install --frozen-lockfile
working-directory: digital-employee-os
- name: Build OS contracts and generate device-cloud Prisma clients
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: device-cloud
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27210
|
2
|
1787706495
|
1787706585
|
1787706493
|
1787706585
|
|
0
|
|
0
|
Edit
Delete
|
|
31121
|
23527
|
82
|
5
|
343e79d764ae566372808d0d922fcef7ca12a30e
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27211
|
2
|
1787706746
|
1787706776
|
1787706744
|
1787706776
|
|
0
|
|
0
|
Edit
Delete
|
|
31123
|
23528
|
76
|
5
|
3cea10da5556cec346fbdecf5255ad38fc2bb92a
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: 22.23.2
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile --ignore-scripts
- name: Rebuild approved dependency scripts
run: pnpm dependencies:rebuild-approved
- name: Audit production dependencies
run: pnpm audit --prod --audit-level high
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
permissions:
contents: read
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27212
|
1
|
1787707096
|
1787707404
|
1787707096
|
1787707404
|
|
0
|
|
0
|
Edit
Delete
|
|
31139
|
23529
|
84
|
5
|
f2a674de3343d5031dee856edd261194709b727f
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27216
|
2
|
1787708896
|
1787708916
|
1787708825
|
1787708917
|
|
0
|
|
0
|
Edit
Delete
|
|
31141
|
23530
|
76
|
5
|
4a222fb5f11f2640e5e3d214e856b703128ee62c
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: 22.23.2
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile --ignore-scripts
- name: Rebuild approved dependency scripts
run: pnpm dependencies:rebuild-approved
- name: Audit production dependencies
run: pnpm audit --prod --audit-level high
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
permissions:
contents: read
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27217
|
1
|
1787708917
|
1787709143
|
1787708829
|
1787709144
|
|
0
|
|
0
|
Edit
Delete
|
|
31157
|
23531
|
81
|
5
|
ce807fe941d01cc4a4a399c474be857407d4aed9
|
0
|
Static governance
|
0
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
steps:
- name: Checkout service system
uses: actions/checkout@v4
with:
path: service-system
- name: Checkout locked Digital Employee OS baseline
uses: actions/checkout@v4
with:
path: digital-employee-os
ref: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.DIGITAL_EMPLOYEE_OS_READ_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build locked Digital Employee OS compatibility packages
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" install --frozen-lockfile
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/skill-runtime build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/tool-runtime build
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: service-system
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1787709129
|
1787708840
|
1787709129
|
|
0
|
|
0
|
Edit
Delete
|
|
31158
|
23531
|
81
|
5
|
ce807fe941d01cc4a4a399c474be857407d4aed9
|
0
|
Runtime and UI acceptance
|
0
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
runtime-acceptance:
name: Runtime and UI acceptance
runs-on: ubuntu-latest
env:
DATABASE_URL: postgresql://postgres:postgres@127.0.0.1:5432/juhai_after_sales_ci?schema=public
REDIS_URL: redis://127.0.0.1:6379
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run real DB and Redis acceptance
run: pnpm check:runtime
- name: Install Playwright browser
run: pnpm --filter web exec playwright install --with-deps chromium
- name: Run UI acceptance
run: pnpm check:ui
services:
postgres:
image: postgres:16
env:
POSTGRES_DB: juhai_after_sales_ci
POSTGRES_PASSWORD: postgres
POSTGRES_USER: postgres
ports:
- 5432:5432
options: --health-cmd "pg_isready -U postgres -d juhai_after_sales_ci" --health-interval 5s --health-timeout 5s --health-retries 20
redis:
image: redis:7
ports:
- 6379:6379
options: --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
runtime-acceptance
|
["static-governance"]
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1787709129
|
1787708840
|
1787709129
|
|
0
|
|
0
|
Edit
Delete
|
|
31159
|
23532
|
81
|
5
|
f7f15c92e83a6df0de98d1d5df4dfdd9b63cd284
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
steps:
- name: Checkout service system
uses: actions/checkout@v4
with:
path: service-system
- name: Checkout locked Digital Employee OS baseline
uses: actions/checkout@v4
with:
path: digital-employee-os
ref: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.DIGITAL_EMPLOYEE_OS_READ_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build locked Digital Employee OS compatibility packages
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" install --frozen-lockfile
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/skill-runtime build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/tool-runtime build
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: service-system
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27218
|
2
|
1787709144
|
1787709151
|
1787709129
|
1787709152
|
|
0
|
|
0
|
Edit
Delete
|
|
31161
|
23533
|
81
|
5
|
158a8d0a3ccc575be23117643ac664ec1b6f73dc
|
0
|
Static governance
|
0
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
steps:
- name: Checkout service system
uses: actions/checkout@v4
with:
path: service-system
- name: Checkout locked Digital Employee OS baseline
uses: actions/checkout@v4
with:
path: digital-employee-os
ref: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.DIGITAL_EMPLOYEE_OS_READ_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build locked Digital Employee OS compatibility packages
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" install --frozen-lockfile
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/skill-runtime build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/tool-runtime build
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: service-system
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1787711431
|
1787710066
|
1787711431
|
|
0
|
|
0
|
Edit
Delete
|
|
31162
|
23533
|
81
|
5
|
158a8d0a3ccc575be23117643ac664ec1b6f73dc
|
0
|
Runtime and UI acceptance
|
0
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
runtime-acceptance:
name: Runtime and UI acceptance
runs-on: ubuntu-latest
env:
DATABASE_URL: postgresql://postgres:postgres@127.0.0.1:5432/juhai_after_sales_ci?schema=public
REDIS_URL: redis://127.0.0.1:6379
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run real DB and Redis acceptance
run: pnpm check:runtime
- name: Install Playwright browser
run: pnpm --filter web exec playwright install --with-deps chromium
- name: Run UI acceptance
run: pnpm check:ui
services:
postgres:
image: postgres:16
env:
POSTGRES_DB: juhai_after_sales_ci
POSTGRES_PASSWORD: postgres
POSTGRES_USER: postgres
ports:
- 5432:5432
options: --health-cmd "pg_isready -U postgres -d juhai_after_sales_ci" --health-interval 5s --health-timeout 5s --health-retries 20
redis:
image: redis:7
ports:
- 6379:6379
options: --health-cmd "redis-cli ping" --health-interval 5s --health-timeout 5s --health-retries 20
...
|
runtime-acceptance
|
["static-governance"]
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1787711431
|
1787710066
|
1787711431
|
|
0
|
|
0
|
Edit
Delete
|
|
31163
|
23534
|
81
|
5
|
fbedaf6d0398693dc8466b4b72b6265d2397d93c
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
steps:
- name: Checkout service system
uses: actions/checkout@v4
with:
path: service-system
- name: Checkout locked Digital Employee OS baseline
uses: actions/checkout@v4
with:
path: digital-employee-os
ref: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.DIGITAL_EMPLOYEE_OS_READ_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build locked Digital Employee OS compatibility packages
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" install --frozen-lockfile
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/skill-runtime build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/tool-runtime build
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: service-system
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27234
|
2
|
1787712441
|
1787712471
|
1787711431
|
1787712471
|
|
0
|
|
0
|
Edit
Delete
|
|
31165
|
23535
|
81
|
5
|
3d56a9a4fb9cccedf11cfdb53a470fa7f29e94c7
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
steps:
- name: Checkout service system
uses: actions/checkout@v4
with:
path: service-system
- name: Checkout locked Digital Employee OS baseline
uses: actions/checkout@v4
with:
path: digital-employee-os
ref: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.DIGITAL_EMPLOYEE_OS_READ_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build locked Digital Employee OS compatibility packages
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" install --frozen-lockfile
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/skill-runtime build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/tool-runtime build
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: service-system
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27235
|
2
|
1787714350
|
1787714358
|
1787714348
|
1787714358
|
|
0
|
|
0
|
Edit
Delete
|
|
31167
|
23536
|
54
|
5
|
53991090b821b76dff11eee3a2e92806ed3ab173
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27236
|
2
|
1787787572
|
1787787593
|
1787787571
|
1787787593
|
|
0
|
|
0
|
Edit
Delete
|
|
31169
|
23537
|
81
|
5
|
466e9752ba0f670d790b5134ff2d12e5b0e974ea
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
DIGITAL_EMPLOYEE_OS_ROOT: ${{ github.workspace }}/digital-employee-os
steps:
- name: Checkout service system
uses: actions/checkout@v4
with:
path: service-system
- name: Checkout locked Digital Employee OS baseline
uses: actions/checkout@v4
with:
path: digital-employee-os
ref: 5cb2f1cc2f9953d47fa0bcfac541400d01603f78
repository: laoluojuhai/digital-employee-os
token: ${{ secrets.DIGITAL_EMPLOYEE_OS_READ_TOKEN }}
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build locked Digital Employee OS compatibility packages
run: |
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" install --frozen-lockfile
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/contracts build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/skill-runtime build
pnpm --dir "$DIGITAL_EMPLOYEE_OS_ROOT" --filter @repo/tool-runtime build
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
defaults:
run:
working-directory: service-system
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27237
|
2
|
1787820687
|
1787820696
|
1787820687
|
1787820696
|
|
0
|
|
0
|
Edit
Delete
|
|
31171
|
23538
|
84
|
5
|
4459ca7bf19df30ae3879f2027b7fb05b3e3ba2d
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27238
|
2
|
1787836636
|
1787836653
|
1787836636
|
1787836653
|
|
0
|
|
0
|
Edit
Delete
|
|
31173
|
23539
|
82
|
5
|
f78be17ac5fecb9cfa36e167b1e85ea26a48fa45
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27239
|
2
|
1787913991
|
1787914025
|
1787913990
|
1787914025
|
|
0
|
|
0
|
Edit
Delete
|
|
31175
|
23540
|
57
|
5
|
0c21eecc828c12daebc00845c14482c3b9d58823
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27240
|
2
|
1787969912
|
1787969939
|
1787969911
|
1787969939
|
|
0
|
|
0
|
Edit
Delete
|
|
31176
|
23541
|
76
|
5
|
fcbd389107386fa0a13d0abd3c8d7c272cc2a7f7
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: 22.23.2
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile --ignore-scripts
- name: Rebuild approved dependency scripts
run: pnpm dependencies:rebuild-approved
- name: Audit production dependencies
run: pnpm audit --prod --audit-level high
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
permissions:
contents: read
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27241
|
2
|
1787979103
|
1787979523
|
1787979102
|
1787979523
|
|
0
|
|
0
|
Edit
Delete
|
|
31192
|
23542
|
90
|
5
|
dcd85b10ac06ae862fe3789b6bd548838487b8fe
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27242
|
2
|
1788052201
|
1788052223
|
1788052201
|
1788052223
|
|
0
|
|
0
|
Edit
Delete
|
|
31194
|
23543
|
91
|
5
|
3c6f499596071037b0035ababe289c015f79d83e
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27243
|
2
|
1788052881
|
1788052901
|
1788052880
|
1788052902
|
|
0
|
|
0
|
Edit
Delete
|
|
31196
|
23544
|
91
|
5
|
3ace3ff6a846bd8e245bbeb090fd28d683945735
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27244
|
2
|
1788053600
|
1788053619
|
1788053599
|
1788053619
|
|
0
|
|
0
|
Edit
Delete
|
|
31198
|
23545
|
91
|
5
|
e20004f4776df6413cdfa4d0b49afdd9bea5b69e
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27245
|
2
|
1788053742
|
1788053761
|
1788053741
|
1788053762
|
|
0
|
|
0
|
Edit
Delete
|
|
31200
|
23546
|
91
|
5
|
e465f302d62150997d35782bfec2304043dd605d
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
# check:os-product 的上游:同实例私有仓,按 SHA 钉版(与本地验收口径一致)。
# 升级流程:先在本地以新 SHA 跑绿 check:os-product(:runtime),再改这里的 OS_SHA。
OS_REPO: luoanwu/digital-employee-os
OS_SHA: fcbd389107386fa0a13d0abd3c8d7c272cc2a7f7
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Checkout Digital Employee OS (check:os-product upstream)
run: |
set -euo pipefail
OS_DIR="$RUNNER_TEMP/digital-employee-os"
rm -rf "$OS_DIR" && mkdir -p "$OS_DIR" && cd "$OS_DIR"
git init -q .
git remote add origin "https://oauth2:${OS_TOKEN}@gitea.g-hi.com/${OS_REPO}.git"
git fetch --depth 1 origin "$OS_SHA"
git checkout -q --detach FETCH_HEAD
echo "DIGITAL_EMPLOYEE_OS_ROOT=$OS_DIR" >> "$GITHUB_ENV"
echo "DIGITAL_EMPLOYEE_OS_SHA=$OS_SHA" >> "$GITHUB_ENV"
env:
OS_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || secrets.GITEA_TOKEN }}
- name: Build Digital Employee OS contracts
run: |
set -euo pipefail
cd "$DIGITAL_EMPLOYEE_OS_ROOT"
pnpm install --frozen-lockfile
pnpm --filter @repo/contracts build
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27246
|
2
|
1788054332
|
1788054370
|
1788054330
|
1788054370
|
|
0
|
|
0
|
Edit
Delete
|
|
31202
|
23547
|
91
|
5
|
fed53f136145fe82cb7dc0a4ee7b8b5453bfddd0
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
# check:os-product 的上游:同实例私有仓,按 SHA 钉版(与本地验收口径一致)。
# 升级流程:先在本地以新 SHA 跑绿 check:os-product(:runtime),再改这里的 OS_SHA。
OS_REPO: luoanwu/digital-employee-os
OS_SHA: fcbd389107386fa0a13d0abd3c8d7c272cc2a7f7
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Checkout Digital Employee OS (check:os-product upstream)
run: |
set -euo pipefail
OS_DIR="$RUNNER_TEMP/digital-employee-os"
rm -rf "$OS_DIR" && mkdir -p "$OS_DIR" && cd "$OS_DIR"
git init -q .
git remote add origin "https://oauth2:${OS_TOKEN}@gitea.g-hi.com/${OS_REPO}.git"
git fetch --depth 1 origin "$OS_SHA"
git checkout -q --detach FETCH_HEAD
echo "DIGITAL_EMPLOYEE_OS_ROOT=$OS_DIR" >> "$GITHUB_ENV"
echo "DIGITAL_EMPLOYEE_OS_SHA=$OS_SHA" >> "$GITHUB_ENV"
env:
OS_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || secrets.GITEA_TOKEN }}
- name: Build Digital Employee OS contracts
run: |
set -euo pipefail
cd "$DIGITAL_EMPLOYEE_OS_ROOT"
pnpm install --frozen-lockfile
pnpm --filter @repo/contracts build
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27247
|
1
|
1788054594
|
1788054657
|
1788054593
|
1788054657
|
|
0
|
|
0
|
Edit
Delete
|
|
31204
|
23548
|
91
|
5
|
625450881bfb787bfa4ac092e11bfe534c340163
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
# check:os-product 的上游:同实例私有仓,按 SHA 钉版(与本地验收口径一致)。
# 升级流程:先在本地以新 SHA 跑绿 check:os-product(:runtime),再改这里的 OS_SHA。
OS_REPO: luoanwu/digital-employee-os
OS_SHA: fcbd389107386fa0a13d0abd3c8d7c272cc2a7f7
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "22"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Checkout Digital Employee OS (check:os-product upstream)
run: |
set -euo pipefail
OS_DIR="$RUNNER_TEMP/digital-employee-os"
rm -rf "$OS_DIR" && mkdir -p "$OS_DIR" && cd "$OS_DIR"
git init -q .
git remote add origin "https://oauth2:${OS_TOKEN}@gitea.g-hi.com/${OS_REPO}.git"
git fetch --depth 1 origin "$OS_SHA"
git checkout -q --detach FETCH_HEAD
echo "DIGITAL_EMPLOYEE_OS_ROOT=$OS_DIR" >> "$GITHUB_ENV"
echo "DIGITAL_EMPLOYEE_OS_SHA=$OS_SHA" >> "$GITHUB_ENV"
env:
OS_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || secrets.GITEA_TOKEN }}
- name: Build Digital Employee OS contracts
run: |
set -euo pipefail
cd "$DIGITAL_EMPLOYEE_OS_ROOT"
pnpm install --frozen-lockfile
pnpm --filter @repo/contracts build
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27249
|
2
|
1788055008
|
1788055099
|
1788055006
|
1788055099
|
|
0
|
|
0
|
Edit
Delete
|
|
31206
|
23549
|
91
|
5
|
b3c5c984414aa860f22c4e16c497d4e25515c067
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
# check:os-product 的上游:同实例私有仓,按 SHA 钉版(与本地验收口径一致)。
# 升级流程:先在本地以新 SHA 跑绿 check:os-product(:runtime),再改这里的 OS_SHA。
OS_REPO: luoanwu/digital-employee-os
OS_SHA: fcbd389107386fa0a13d0abd3c8d7c272cc2a7f7
# Digital Employee OS 的 engines 要求 node >=22(本仓自身 >=20,取并集)
NODE_VERSION: v22.16.0
steps:
- name: Checkout (shell, full history)
run: |
set -euo pipefail
cd "$GITHUB_WORKSPACE"
HOST_PATH="${GITHUB_SERVER_URL#*://}"
git init -q .
git remote remove origin 2>/dev/null || true
git remote add origin "https://oauth2:${CLONE_TOKEN}@${HOST_PATH}/${GITHUB_REPOSITORY}.git"
git fetch -q origin "$GITHUB_SHA"
git checkout -q -f --detach "$GITHUB_SHA"
git clean -fdxq -e node_modules -e .turbo
git log --oneline -1
env:
CLONE_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || github.token }}
- name: Provision Node.js (npmmirror)
run: |
set -euo pipefail
case "$(uname -m)" in
x86_64) NODE_ARCH=x64 ;;
aarch64|arm64) NODE_ARCH=arm64 ;;
*) echo "::error::未支持的 runner 架构 $(uname -m)"; exit 1 ;;
esac
NODE_DIR="$RUNNER_TEMP/node-${NODE_VERSION}-${NODE_ARCH}"
if [ ! -x "$NODE_DIR/bin/node" ]; then
mkdir -p "$NODE_DIR"
curl -fsSL "https://cdn.npmmirror.com/binaries/node/${NODE_VERSION}/node-${NODE_VERSION}-linux-${NODE_ARCH}.tar.xz" \
| tar -xJ -C "$NODE_DIR" --strip-components 1
fi
echo "$NODE_DIR/bin" >> "$GITHUB_PATH"
"$NODE_DIR/bin/node" --version
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm --version
- name: Checkout Digital Employee OS (check:os-product upstream)
run: |
set -euo pipefail
HOST_PATH="${GITHUB_SERVER_URL#*://}"
OS_DIR="$RUNNER_TEMP/digital-employee-os"
rm -rf "$OS_DIR" && mkdir -p "$OS_DIR" && cd "$OS_DIR"
git init -q .
git remote add origin "https://oauth2:${OS_TOKEN}@${HOST_PATH}/${OS_REPO}.git"
git fetch -q --depth 1 origin "$OS_SHA"
git checkout -q --detach FETCH_HEAD
echo "DIGITAL_EMPLOYEE_OS_ROOT=$OS_DIR" >> "$GITHUB_ENV"
echo "DIGITAL_EMPLOYEE_OS_SHA=$OS_SHA" >> "$GITHUB_ENV"
env:
OS_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || github.token }}
- name: Build Digital Employee OS contracts
run: |
set -euo pipefail
cd "$DIGITAL_EMPLOYEE_OS_ROOT"
pnpm install --frozen-lockfile
pnpm --filter @repo/contracts build
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27250
|
1
|
1788055431
|
1788055490
|
1788055430
|
1788055490
|
|
0
|
|
0
|
Edit
Delete
|
|
31208
|
23550
|
91
|
5
|
284009be92a0f6d8f79682120be0421fa0d80387
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
# check:os-product 的上游:同实例私有仓,按 SHA 钉版(与本地验收口径一致)。
# 升级流程:先在本地以新 SHA 跑绿 check:os-product(:runtime),再改这里的 OS_SHA。
OS_REPO: luoanwu/digital-employee-os
OS_SHA: fcbd389107386fa0a13d0abd3c8d7c272cc2a7f7
# Digital Employee OS 的 engines 要求 node >=22(本仓自身 >=20,取并集)
NODE_VERSION: v22.16.0
steps:
- name: Checkout (shell, full history)
run: |
set -euo pipefail
cd "$GITHUB_WORKSPACE"
HOST_PATH="${GITHUB_SERVER_URL#*://}"
git init -q .
git remote remove origin 2>/dev/null || true
git remote add origin "https://oauth2:${CLONE_TOKEN}@${HOST_PATH}/${GITHUB_REPOSITORY}.git"
git fetch -q origin "$GITHUB_SHA"
git checkout -q -f --detach "$GITHUB_SHA"
git clean -fdxq -e node_modules -e .turbo
git log --oneline -1
env:
CLONE_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || github.token }}
- name: Provision Node.js (npmmirror)
run: |
set -euo pipefail
case "$(uname -m)" in
x86_64) NODE_ARCH=x64 ;;
aarch64|arm64) NODE_ARCH=arm64 ;;
*) echo "::error::未支持的 runner 架构 $(uname -m)"; exit 1 ;;
esac
NODE_DIR="$RUNNER_TEMP/node-${NODE_VERSION}-${NODE_ARCH}"
if [ ! -x "$NODE_DIR/bin/node" ]; then
mkdir -p "$NODE_DIR"
curl -fsSL "https://cdn.npmmirror.com/binaries/node/${NODE_VERSION}/node-${NODE_VERSION}-linux-${NODE_ARCH}.tar.xz" \
| tar -xJ -C "$NODE_DIR" --strip-components 1
fi
echo "$NODE_DIR/bin" >> "$GITHUB_PATH"
"$NODE_DIR/bin/node" --version
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm --version
- name: Checkout Digital Employee OS (check:os-product upstream)
run: |
set -euo pipefail
HOST_PATH="${GITHUB_SERVER_URL#*://}"
OS_DIR="$RUNNER_TEMP/digital-employee-os"
rm -rf "$OS_DIR" && mkdir -p "$OS_DIR" && cd "$OS_DIR"
git init -q .
git remote add origin "https://oauth2:${OS_TOKEN}@${HOST_PATH}/${OS_REPO}.git"
git fetch -q --depth 1 origin "$OS_SHA"
git checkout -q --detach FETCH_HEAD
echo "DIGITAL_EMPLOYEE_OS_ROOT=$OS_DIR" >> "$GITHUB_ENV"
echo "DIGITAL_EMPLOYEE_OS_SHA=$OS_SHA" >> "$GITHUB_ENV"
env:
OS_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || github.token }}
- name: Build Digital Employee OS contracts
run: |
set -euo pipefail
cd "$DIGITAL_EMPLOYEE_OS_ROOT"
pnpm install --frozen-lockfile
pnpm --filter @repo/contracts build
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27252
|
1
|
1788056210
|
1788056268
|
1788056209
|
1788056268
|
|
0
|
|
0
|
Edit
Delete
|
|
31210
|
23551
|
91
|
5
|
2235838932d2a3dd2f545bf0f33073983a45ae60
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
# check:os-product 的上游:同实例私有仓,按 SHA 钉版(与本地验收口径一致)。
# 升级流程:先在本地以新 SHA 跑绿 check:os-product(:runtime),再改这里的 OS_SHA。
OS_REPO: luoanwu/digital-employee-os
OS_SHA: fcbd389107386fa0a13d0abd3c8d7c272cc2a7f7
# Digital Employee OS 的 engines 要求 node >=22(本仓自身 >=20,取并集)
NODE_VERSION: v22.16.0
steps:
- name: Checkout (shell, full history)
run: |
set -euo pipefail
cd "$GITHUB_WORKSPACE"
HOST_PATH="${GITHUB_SERVER_URL#*://}"
git init -q .
git remote remove origin 2>/dev/null || true
git remote add origin "https://oauth2:${CLONE_TOKEN}@${HOST_PATH}/${GITHUB_REPOSITORY}.git"
git fetch -q origin "$GITHUB_SHA"
git checkout -q -f --detach "$GITHUB_SHA"
git clean -fdxq -e node_modules -e .turbo
git log --oneline -1
env:
CLONE_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || github.token }}
- name: Provision Node.js (npmmirror)
run: |
set -euo pipefail
case "$(uname -m)" in
x86_64) NODE_ARCH=x64 ;;
aarch64|arm64) NODE_ARCH=arm64 ;;
*) echo "::error::未支持的 runner 架构 $(uname -m)"; exit 1 ;;
esac
NODE_DIR="$RUNNER_TEMP/node-${NODE_VERSION}-${NODE_ARCH}"
if [ ! -x "$NODE_DIR/bin/node" ]; then
mkdir -p "$NODE_DIR"
curl -fsSL "https://cdn.npmmirror.com/binaries/node/${NODE_VERSION}/node-${NODE_VERSION}-linux-${NODE_ARCH}.tar.xz" \
| tar -xJ -C "$NODE_DIR" --strip-components 1
fi
echo "$NODE_DIR/bin" >> "$GITHUB_PATH"
"$NODE_DIR/bin/node" --version
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm --version
- name: Checkout Digital Employee OS (check:os-product upstream)
run: |
set -euo pipefail
HOST_PATH="${GITHUB_SERVER_URL#*://}"
OS_DIR="$RUNNER_TEMP/digital-employee-os"
rm -rf "$OS_DIR" && mkdir -p "$OS_DIR" && cd "$OS_DIR"
git init -q .
git remote add origin "https://oauth2:${OS_TOKEN}@${HOST_PATH}/${OS_REPO}.git"
git fetch -q --depth 1 origin "$OS_SHA"
git checkout -q --detach FETCH_HEAD
echo "DIGITAL_EMPLOYEE_OS_ROOT=$OS_DIR" >> "$GITHUB_ENV"
echo "DIGITAL_EMPLOYEE_OS_SHA=$OS_SHA" >> "$GITHUB_ENV"
env:
OS_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || github.token }}
- name: Build Digital Employee OS contracts
run: |
set -euo pipefail
cd "$DIGITAL_EMPLOYEE_OS_ROOT"
pnpm install --frozen-lockfile
pnpm --filter @repo/contracts build
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27254
|
1
|
1788057142
|
1788057201
|
1788057141
|
1788057202
|
|
0
|
|
0
|
Edit
Delete
|
|
31212
|
23552
|
91
|
5
|
48c7ef665e210ef004970fc6f1fdc443a03b48a1
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
env:
# check:os-product 的上游:同实例私有仓,按 SHA 钉版(与本地验收口径一致)。
# 升级流程:先在本地以新 SHA 跑绿 check:os-product(:runtime),再改这里的 OS_SHA。
OS_REPO: luoanwu/digital-employee-os
OS_SHA: fcbd389107386fa0a13d0abd3c8d7c272cc2a7f7
# Digital Employee OS 的 engines 要求 node >=22(本仓自身 >=20,取并集)
NODE_VERSION: v22.16.0
steps:
- name: Checkout (shell, full history)
run: |
set -euo pipefail
cd "$GITHUB_WORKSPACE"
HOST_PATH="${GITHUB_SERVER_URL#*://}"
git init -q .
git remote remove origin 2>/dev/null || true
git remote add origin "https://oauth2:${CLONE_TOKEN}@${HOST_PATH}/${GITHUB_REPOSITORY}.git"
git fetch -q origin "$GITHUB_SHA"
git checkout -q -f --detach "$GITHUB_SHA"
git clean -fdxq -e node_modules -e .turbo
git log --oneline -1
env:
CLONE_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || github.token }}
- name: Provision Node.js (npmmirror)
run: |
set -euo pipefail
case "$(uname -m)" in
x86_64) NODE_ARCH=x64 ;;
aarch64|arm64) NODE_ARCH=arm64 ;;
*) echo "::error::未支持的 runner 架构 $(uname -m)"; exit 1 ;;
esac
NODE_DIR="$RUNNER_TEMP/node-${NODE_VERSION}-${NODE_ARCH}"
if [ ! -x "$NODE_DIR/bin/node" ]; then
mkdir -p "$NODE_DIR"
curl -fsSL "https://cdn.npmmirror.com/binaries/node/${NODE_VERSION}/node-${NODE_VERSION}-linux-${NODE_ARCH}.tar.xz" \
| tar -xJ -C "$NODE_DIR" --strip-components 1
fi
echo "$NODE_DIR/bin" >> "$GITHUB_PATH"
"$NODE_DIR/bin/node" --version
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
pnpm --version
- name: Checkout Digital Employee OS (check:os-product upstream)
run: |
set -euo pipefail
HOST_PATH="${GITHUB_SERVER_URL#*://}"
OS_DIR="$RUNNER_TEMP/digital-employee-os"
rm -rf "$OS_DIR" && mkdir -p "$OS_DIR" && cd "$OS_DIR"
git init -q .
git remote add origin "https://oauth2:${OS_TOKEN}@${HOST_PATH}/${OS_REPO}.git"
git fetch -q --depth 1 origin "$OS_SHA"
git checkout -q --detach FETCH_HEAD
echo "DIGITAL_EMPLOYEE_OS_ROOT=$OS_DIR" >> "$GITHUB_ENV"
echo "DIGITAL_EMPLOYEE_OS_SHA=$OS_SHA" >> "$GITHUB_ENV"
env:
OS_TOKEN: ${{ secrets.OS_CHECKOUT_TOKEN || github.token }}
- name: Build Digital Employee OS contracts
run: |
set -euo pipefail
cd "$DIGITAL_EMPLOYEE_OS_ROOT"
pnpm install --frozen-lockfile
pnpm --filter @repo/contracts build
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27256
|
1
|
1788058397
|
1788058457
|
1788058396
|
1788058457
|
|
0
|
|
0
|
Edit
Delete
|
|
31214
|
23553
|
90
|
5
|
46dce73b5cfc83e6e6cfb87922f22faee76fdd28
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27258
|
2
|
1788059669
|
1788059693
|
1788059668
|
1788059693
|
|
0
|
|
0
|
Edit
Delete
|
|
31216
|
23554
|
76
|
5
|
d433548ec7561644062b04334161019919ea233d
|
0
|
Static governance
|
1
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
static-governance:
name: Static governance
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
fetch-depth: "0"
- name: Setup Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020
with:
node-version: 22.23.2
- name: Enable pnpm
run: |
corepack enable
corepack prepare pnpm@9.15.9 --activate
- name: Install dependencies
run: pnpm install --frozen-lockfile --ignore-scripts
- name: Rebuild approved dependency scripts
run: pnpm dependencies:rebuild-approved
- name: Audit production dependencies
run: pnpm audit --prod --audit-level high
- name: Generate Prisma clients
run: pnpm prisma:generate
- name: Run static governance gate
run: pnpm check
permissions:
contents: read
...
|
static-governance
|
null
|
["ubuntu-latest"]
|
27259
|
3
|
1788059693
|
1788059710
|
1788059683
|
1788059710
|
|
0
|
|
0
|
Edit
Delete
|
|
31217
|
23554
|
76
|
5
|
d433548ec7561644062b04334161019919ea233d
|
0
|
Application image scan (api-fastify)
|
0
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
application-image-vulnerability-scan:
name: Application image scan (api-fastify)
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
fetch-depth: "0"
- name: Build immutable application target
run: docker build --target "${{ matrix.target }}" --tag "${{ matrix.image }}" --file deploy/production/Dockerfile .
env:
DOCKER_BUILDKIT: "1"
- if: matrix.target == 'ops-postgres'
name: Verify hardened PostgreSQL runtime
run: node scripts/check-postgres-image.mjs "${{ matrix.image }}"
- if: matrix.target == 'ops-alertmanager'
name: Verify reduced Alertmanager runtime
run: node scripts/check-alertmanager-image.mjs "${{ matrix.image }}"
- if: matrix.target == 'ops-loki'
name: Verify rebuilt Loki runtime
run: node scripts/check-loki-image.mjs "${{ matrix.image }}"
- if: matrix.target == 'ops-tempo'
name: Verify rebuilt Tempo runtime
run: node scripts/check-tempo-image.mjs "${{ matrix.image }}"
- if: matrix.target == 'ops-otel-collector'
name: Verify minimal OTel Collector runtime
run: node scripts/check-otel-collector-image.mjs "${{ matrix.image }}"
- name: Reject application HIGH or CRITICAL vulnerabilities
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25
with:
exit-code: "1"
format: table
ignore-unfixed: "false"
image-ref: ${{ matrix.image }}
scanners: vuln
severity: CRITICAL,HIGH
trivy-version: v0.74.0
vuln-type: os,library
strategy:
fail-fast: "false"
matrix:
image:
- deos-scan-api-fastify:ci
target:
- api-fastify
permissions:
contents: read
...
|
application-image-vulnerability-scan
|
["static-governance"]
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1788059711
|
1788059683
|
1788059711
|
|
0
|
|
0
|
Edit
Delete
|
|
31218
|
23554
|
76
|
5
|
d433548ec7561644062b04334161019919ea233d
|
0
|
Application image scan (api-nestjs)
|
0
|
name: Governance
"on":
pull_request:
name: Governance
"on":
pull_request:
push:
branches:
- main
jobs:
application-image-vulnerability-scan:
name: Application image scan (api-nestjs)
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
fetch-depth: "0"
- name: Build immutable application target
run: docker build --target "${{ matrix.target }}" --tag "${{ matrix.image }}" --file deploy/production/Dockerfile .
env:
DOCKER_BUILDKIT: "1"
- if: matrix.target == 'ops-postgres'
name: Verify hardened PostgreSQL runtime
run: node scripts/check-postgres-image.mjs "${{ matrix.image }}"
- if: matrix.target == 'ops-alertmanager'
name: Verify reduced Alertmanager runtime
run: node scripts/check-alertmanager-image.mjs "${{ matrix.image }}"
- if: matrix.target == 'ops-loki'
name: Verify rebuilt Loki runtime
run: node scripts/check-loki-image.mjs "${{ matrix.image }}"
- if: matrix.target == 'ops-tempo'
name: Verify rebuilt Tempo runtime
run: node scripts/check-tempo-image.mjs "${{ matrix.image }}"
- if: matrix.target == 'ops-otel-collector'
name: Verify minimal OTel Collector runtime
run: node scripts/check-otel-collector-image.mjs "${{ matrix.image }}"
- name: Reject application HIGH or CRITICAL vulnerabilities
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25
with:
exit-code: "1"
format: table
ignore-unfixed: "false"
image-ref: ${{ matrix.image }}
scanners: vuln
severity: CRITICAL,HIGH
trivy-version: v0.74.0
vuln-type: os,library
strategy:
fail-fast: "false"
matrix:
image:
- deos-scan-api-nestjs:ci
target:
- api-nestjs
permissions:
contents: read
...
|
application-image-vulnerability-scan
|
["static-governance"]
|
["ubuntu-latest"]
|
0
|
3
|
0
|
1788059711
|
1788059683
|
1788059711
|
|
0
|
|
0
|
Edit
Delete
|